Known Vulnerabilities for Joomla! by Joomla
Listed below are 10 of the newest known vulnerabilities associated with "Joomla!" by "Joomla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88857 json | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Jo... | Not Provided | 2026-09-20 | 2026-09-20 |
| CVE-2026-88856 json | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Jo... | Not Provided | 2026-09-20 | 2026-09-20 |
| CVE-2026-88855 json | Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6... | Not Provided | 2026-09-20 | 2026-09-20 |
| CVE-2026-88854 json | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The... | Not Provided | 2026-09-20 | 2026-09-20 |
| CVE-2026-88853 json | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0... | Not Provided | 2026-09-14 | 2026-09-15 |
| CVE-2026-88852 json | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snip... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-85196 json | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extensi... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-85195 json | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-85192 json | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joo... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-85191 json | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < ... | Not Provided | 2026-09-14 | 2026-09-15 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 4.0.0 | |||
| Application | Joomla | Joomla! | 3.9.9 | |||
| Application | Joomla | Joomla! | 3.9.8 | |||
| Application | Joomla | Joomla! | 3.9.7 | |||
| Application | Joomla | Joomla! | 3.9.7 | |||
| Application | Joomla | Joomla! | 3.9.7 | |||
| Application | Joomla | Joomla! | 3.9.6 | |||
| Application | Joomla | Joomla! | 3.9.6 | |||
| Application | Joomla | Joomla! | 3.9.6 | |||
| Application | Joomla | Joomla! | 3.9.5 |